in reply to daniel:// stenberg://

That would explain both the increase in volume and the drop in accuracy.

I was secretly hoping it would be a mix of "the code is becoming less vulnerable each year" and "more people than ever are interested in hunting bugs, so we're seeing an influx of new blood and obviously these people aren't as good as the old hunters... yet".

I have such a strong dislike for LLMs that I feel the bias and perhaps hope to be proven wrong about how destructive it is.

This entry was edited (1 week ago)
in reply to daniel:// stenberg://

Interesting! Thanks for sharing. Sequoia received 74 reports this year on yeswehack and we've confirmed 6 vulnerabilities. Of those, none were serious. Two had to do with wasting resources on specially crafted input. Two were out of bounds array accesses that result in a panic (we're using rust). One was a terminal injection, because we forgot to escape attacker controlled data that we print. And the last one was forgetting to check that the value returned from malloc is not NULL.